feat(auth): coordinate canonical projection publication

This commit is contained in:
User
2026-08-21 23:43:37 +02:00
parent 1e2c4e65c5
commit 903c0b4de5
10 changed files with 1272 additions and 8 deletions
@@ -1,16 +1,44 @@
package authconfig
import (
"bytes"
"errors"
"os"
"path/filepath"
"strings"
"testing"
"github.com/aritmolab/thothii/tools/tht/internal/authprojection"
"github.com/aritmolab/thothii/tools/tht/internal/safeio"
"github.com/aritmolab/thothii/tools/tht/internal/testsupport"
)
func TestLoadSnapshotBytesReturnsValidatedCopiedCanonicalBytes(t *testing.T) {
for _, fixture := range []struct{ name, auth, users string }{
{"local", defaultAuthYAML, registryYAML(adminUserYAML("admin", "Admin", true, "admin"))},
{"oidc", "version: 1\nmode: oidc\npublicUrl: https://example.invalid\n", ""},
} {
t.Run(fixture.name, func(t *testing.T) {
directory := writeAuthFiles(t, fixture.auth, fixture.users)
snapshot, err := loadSnapshotBytes(directory)
if err != nil {
t.Fatal(err)
}
if snapshot.Mode != fixture.name || !bytes.Equal(snapshot.Auth, []byte(fixture.auth)) || !bytes.Equal(snapshot.Users, []byte(fixture.users)) {
t.Fatal("loadSnapshotBytes() did not preserve the validated canonical bytes")
}
if _, err := authprojection.NewSnapshot(snapshot.Mode, snapshot.Auth, snapshot.Users); err != nil {
t.Fatalf("loadSnapshotBytes() returned invalid projection data: %v", err)
}
snapshot.Auth[0] ^= 1
onDisk, err := os.ReadFile(filepath.Join(directory, authFileName))
if err != nil || !bytes.Equal(onDisk, []byte(fixture.auth)) {
t.Fatal("loadSnapshotBytes() returned aliasing canonical storage")
}
})
}
}
const publicFixedHash = "$argon2id$v=19$m=65536,t=3,p=1$AAECAwQFBgcICQoLDA0ODw$DRo8ZSPI8G5OCvnFFapbVEjP69aDjy1Sw9i2743cPC4"
func TestLoadReadsTheStrictLocalConfigurationAndRegistry(t *testing.T) {